Legal Sentinel Blog — Vendor Compliance Insights for RIAs

Practical guidance on vendor oversight, Reg S-P compliance, and TPRM for RIA compliance teams — grounded in what examiners actually check, not trend pieces.

What Should a Vendor Due Diligence Questionnaire Cover for RIA Compliance
Vendor Risk & Oversight

What Should a Vendor Due Diligence Questionnaire Cover for RIA Compliance?

A vendor due diligence questionnaire for RIAs should cover cybersecurity, Reg S-P safeguards, subcontractor use, financial stability, and ongoing monitoring commitments.

Emily Mora · July 31, 2026
How Often Should RIAs Review Vendor Contracts for Compliance?
Vendor Risk & Oversight

How Often Should RIAs Review Vendor Contracts for Compliance?

No fixed interval exists. Standard practice: annual review for vendors touching client data, cybersecurity, or investment ops — continuous monitoring between reviews, and immediate ad hoc review after a breach, material change, or new subprocessor. Annual-only no longer satisfies SEC scrutiny.

Emily Mora · July 19, 2026
What Does Reg S-P's Vendor Oversight Requirement Actually Require RIAs to Do?
Regulatory Compliance

What Does Reg S-P's Vendor Oversight Requirement Actually Require RIAs to Do?

Reg S-P's June 3, 2026 deadline requires RIAs to oversee service providers with access to customer data. Here's what that actually means in practice.

Emily Mora · July 10, 2026